
StreamSend WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/streamsend-for-wordpressAdd a StreamSend Signup Form to Your Website
Is StreamSend WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 85/100StreamSend WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "streamsend-for-wordpress" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no known vulnerabilities or CVEs in its history. The absence of file operations and external HTTP requests in the static analysis also reduces potential attack vectors. However, there are significant concerns regarding output escaping and the lack of nonces and capability checks. The fact that 100% of its single output is not properly escaped presents a direct risk of cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is reflected directly into the output. Furthermore, the absence of any nonce checks or capability checks on its entry points (shortcodes) means that these can be triggered by any logged-in user, or potentially even unauthenticated users if the shortcodes themselves don't have implicit authorization checks. The vulnerability history is clean, which is encouraging, but the static analysis reveals potential weaknesses that could lead to vulnerabilities if not addressed. The overall risk is moderate, primarily due to the unescaped output and lack of authorization controls on its entry points.
Key Concerns
- 100% of outputs not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
StreamSend WordPress Plugin Security Vulnerabilities
StreamSend WordPress Plugin Code Analysis
Output Escaping
StreamSend WordPress Plugin Attack Surface
Shortcodes 2
Maintenance & Trust
StreamSend WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
StreamSend WordPress Plugin Alternatives
Newsletter Subscription Form – User Subscriptions Form, Capture Email
newsletter-subscription-form
Newsletter Subscription Form for WordPress is the ultimate lead generation, customer acquisition and email marketing plugin to grow and engage your ma …
Email Subscribers – Group Selector
email-subscribers-advanced-form
Add-on for Email Subscribers plugin using which you can provide option to your users to select interested groups in the Subscribe Form.
Constant Contact WordPress Widget
constant-contact-signup-form-widget
Easily add Constant Contact signup forms to your website (sidebar or content) and configure how they look.
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Mailjet Email Marketing
mailjet-for-wordpress
Includes WooCommerce automated and order emails. Design, send and track engaging marketing and transactional emails from your WordPress admin.
StreamSend WordPress Plugin Developer Profile
23 plugins · 14K total installs
How We Detect StreamSend WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
http://app.streamsend.com/public/z3du/8KJ/subscribehttp://www.streamsend.com